Skip to content

Privacy and preparation

Zendesk redaction: what it removes and what it misses

By SourceX Editorial · Updated

Short answer

Zendesk's native and add-on redaction tools are built to remove specific sensitive content from live tickets, such as a card number a customer pasted into a comment. They are not built to prepare years of history for licensing. Subject lines, fields, user profiles, audits and attachments need their own handling, and the safer approach is to redact an exported copy.

Key takeaways

  • In-product redaction permanently changes live tickets, so use it for incidents, not for preparing a licensing dataset.
  • Personal details also live in subject lines, custom fields, user and organization records, tags, audits and attachments.
  • Many redaction integrations act on new tickets as they arrive, so historical tickets need a separate backfill.
  • For licensing, export the history, redact the copy, review a risk-ranked queue and leave the live instance untouched.

What is Zendesk redaction designed to do?#

Zendesk redaction is designed to remove a specific piece of sensitive content from a ticket after it has been captured, such as a password, a card number or a document a customer should not have sent. The removal is permanent in the live ticket, which is exactly what an agent handling a privacy incident wants.

Licensing asks a different question. Instead of removing one known item from one ticket, you need to find every personal detail across years of tickets, users and attachments, including details nobody has noticed yet. Tools built for the first job leave gaps when stretched to the second.

The redaction features available to you depend on your plan, on add-ons such as Zendesk's Advanced Data Privacy and Protection add-on, and on any marketplace apps installed. Check Zendesk's current documentation for your account before relying on any capability described here in general terms.

Native, add-on and API options compared#

Redaction options around Zendesk fall into a handful of types. The table describes each type in general terms and lists what to verify, because scope differs by plan and changes over time.

Native, add-on and API options compared
Option typeTypical scopeWhat to verifyGap for licensing history
Agent redaction in the ticket viewSelected text or attachments in one ticketWhich roles can redact; whether closed tickets and every channel are coveredOne ticket at a time; relies on someone spotting the detail
Automatic detection in the product or an add-onPatterned items such as payment card numbersWhich patterns are detected; whether past tickets and attachments are includedPatterns only; names and context are missed
Marketplace redaction appsSearch for a known string and redact it across ticketsPermissions, attachment support, side conversationsFinds only what you already know to look for
API-driven redactionProgrammatic redaction of comment text and attachmentsRate limits, archived tickets, audit trailEdits production records irreversibly
Third-party data loss prevention integrationsDetection as new tickets arriveWhether a historical backfill is offeredOften forward-only unless backfilled
Redacting an exported copyEverything exported: comments, fields, users, attachmentsExport completeness and attachment downloadsNeeds your own pipeline and review

Where personal details sit outside ticket comments#

Personal details in a Zendesk account sit in many places beyond comment text, and redacting a comment changes none of them. Build the export and redaction scope around this list, then confirm each item against your own instance.

  • Ticket subject lines, which customers often write as their name plus a problem.
  • Requester, CC and follower records, with names, emails, phone numbers and user fields.
  • Organization records and fields, such as account owner or site contact.
  • Custom ticket fields, especially free-text fields added for an old workflow.
  • Tags, where teams have tagged tickets with customer or employee names.
  • Ticket audits and events, which can keep earlier field values after a field is edited.
  • Side conversations, chat and messaging transcripts, and voice recordings or call transcripts.
  • Satisfaction survey comments, macros and agent signatures.
  • Quoted email replies, signatures and inline images inside comments.
  • Attachments of every kind, from screenshots to spreadsheets.

Why licensing calls for redacting an export, not live tickets#

Licensing calls for redacting an exported copy because in-place redaction cannot be undone and removes context the business still uses. Support teams rely on full history for repeat customers, warranty questions and disputes, and some tickets may be under retention duties or legal holds.

Why licensing calls for redacting an export, not live tickets
QuestionRedact live ticketsRedact an exported copy
Effect on daily supportAgents lose context on past ticketsNone; the live instance is untouched
ReversibilityPermanentRe-run the pipeline with better rules at any time
CoverageLimited to what each feature reachesEvery exported object, including fields and attachments
Retention and legal holdsRisk of altering held recordsOriginals preserved
Evidence for a licenseeHard to show what was removed and whyConfiguration, queue decisions and samples are logged

A bulk approach for years of ticket history#

A bulk approach treats Zendesk as a source system and does the redaction elsewhere. The steps assume an IT lead with API access and a controlled workspace for the copy.

Check what your plan and settings allow before promising a scope. Zendesk's account data export tools are not available on Team plans and must be switched on by Zendesk Customer Support at the account owner's request, although every plan can export through the REST API. Zendesk also archives tickets automatically 120 days after they are closed. Archived tickets stay reachable through search, user profiles and API endpoints but drop out of views, so an export assembled from views can silently skip most of your history.

Look for ticket deletion schedules in Admin Center before the first export. A schedule keeps deleting archived tickets that match its criteria while your project runs, and deleted tickets cannot be restored.

  • Export tickets, comments, users, organizations, custom fields and audits through the API, and download attachments as files instead of keeping links.
  • Test one small date range from each year of history, including archived tickets, before committing to a scope.
  • Freeze the export with a date and a checksum so every later run works on the same copy.
  • Decide exclusions first: voice recordings, HR-related views and tickets from customers whose contracts restrict use.
  • Run automated detection on every text field, using your own user and organization lists as dictionaries of known names.
  • Send long threads, escalations, low-confidence detections and kept attachments to a human review queue.
  • Draw a random sample of the output for QA, fix any rule behind a miss and re-run the affected slice.
  • Package the result with a field map that explains each column and placeholder.

Illustrative: a scheduling software company prepares its Zendesk history#

Illustrative: a fictional scheduling platform for commercial cleaning companies has used Zendesk since its early years. Its tickets connect customer questions to bugs in Jira and to release notes, the kind of linked history that shows how product problems were actually solved.

The support manager first tries a marketplace redaction app on old tickets, then stops on realizing that each edit is permanent and the app finds only strings someone types in. The CTO switches to an export: tickets, users, organizations, custom fields, audits and attachments go into a locked workspace.

Detection finds the expected emails and phone numbers. Review finds more: a free-text custom field called site contact holds cleaners' names, ticket subjects carry customer names, and the audit trail keeps old values of that custom field. The team redacts all three, excludes voice recordings and spreadsheets, and leaves the live Zendesk account exactly as it was.

How SourceX approaches Zendesk history#

SourceX treats Zendesk as one source system during Supply, the first stage of the SourceX five-step transaction. At that point SourceX looks only at descriptive details, such as how many years of tickets exist, which channels feed them, which custom fields are in use and whether tickets link to engineering issues; no ticket content changes hands.

Rights questions, such as customer contract limits on support data, are settled in the Rights step. In Preparation, redaction runs on the exported copy, and the field map, exclusions, queue rules and QA results go into the privacy record of the SourceX Evidence Packet.

Frequently asked questions

Does redacting a ticket also clean copies we already exported?

No. Earlier exports, data synced to a warehouse or CRM, and email notifications already sent stay as they were. For how Zendesk itself handles redacted content, check its documentation and your agreement. List every copy you hold before treating any redaction as complete.

Should internal notes be included in a licensing dataset?

Often they are the most useful part, because they show how agents reasoned about a problem. They also hold the most candid language about customers and colleagues. Include them only after review, and exclude notes that discuss individual employees, disputes or legal matters.

Do business customers change the privacy picture?

Partly. Business customers bring contract terms that may limit how support data is used, and the people who write in are still individuals with names and email addresses. Check customer contracts in the rights review, then remove personal details of contacts and agents during preparation.

Can deletion schedules and licensing coexist?

Yes, if the export respects them. Tickets due for deletion under your retention schedule, or covered by a deletion request, should not appear in the licensing copy. Apply deletions to the export before preparation and record the cut-off date you used.

What happens to ticket history if we cancel Zendesk?

It is deleted. Under Zendesk's Service Data Deletion Policy, an automated process that permanently deletes the account's Service Data starts 90 days after the account is canceled or terminated, and it cannot be reversed once it starts. If a help desk migration or shutdown is planned, finish and verify the licensing export first, and confirm the current policy against your own contract.

Sources

  • Zendesk's account data export tools are not available on Team plans, but customers on every plan can export data through the Zendesk REST API; data exports are not turned on by default and the account owner must contact Zendesk Customer Support to enable them. Source
  • Zendesk automatically archives tickets 120 days after they reach Closed status; archived tickets can still be found by search, direct link, user profile and API endpoints, but do not appear in views. Source
  • Zendesk ticket deletion schedules delete archived tickets after a set period; deleted tickets cannot be restored, and schedules keep deleting any tickets that match their criteria. Source
  • Under Zendesk's Service Data Deletion Policy, an automated process that permanently deletes the account's Service Data starts 90 days after the account is canceled or terminated, and once it starts it cannot be reversed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify